Staff Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $139k - $218k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Mozilla

Mozilla

501 - 1000 employees

Founded 1998

👥 B2C

🔒 Cybersecurity

B2C • Cybersecurity • Software

Mozilla is a non-profit organization dedicated to promoting an open and accessible internet. They are the makers of the popular Firefox browser, which emphasizes user privacy, speed, and control. Mozilla also offers a range of products that focus on internet security and privacy, including Mozilla VPN, Firefox Relay, and Mozilla Monitor. Additionally, the organization is involved in open-source projects, AI innovation, and advocating for digital rights. Mozilla aims to empower users with trustworthy technology and policies that protect privacy, support open-source AI development, and foster accountability for tech companies.

📋 Description

• Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence. • Support ISO 27001 and SOC 2 Type 2 audit execution, including scope determination, evidence and narrative preparation, auditor interviews and walkthroughs, and resolution of auditor findings. • Contribute to the SOC 2 System Description and other audit-specific narrative documentation. • Track gaps and remediation efforts arising from readiness assessments and audits. • Lead the security policy program, including policy creation, revision, and cross-functional review cycles. • Support compliance scaling as additional products or business units pursue readiness assessments and certification. • Support the internal audit function with internal or third-party resources. • Partner with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical practices. • Advise the GRC manager and Security leadership on audit risk, certification readiness, and compliance program strategy.

🎯 Requirements

• 5 years of experience in information security, GRC, or compliance-focused roles. • Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria, including meaningful involvement in audits from readiness through certification. • Experience across the full breadth of an ISMS, including SoA maintenance, Management Review Meetings, and System Description authorship. • Demonstrated experience writing and revising security policies and running cross-functional review cycles. • Experience tracking gaps and remediation plans within a broader compliance and risk program. • Ability to collaborate with engineers, product managers, legal, and executive stakeholders and translate compliance requirements into practical workflows. • Ability to ramp up quickly and operate independently. • Comfort building processes where none yet exist. • Strong written and verbal communication skills and ability to represent Mozilla before external auditors. • Relevant industry certifications such as CISA, CISSP, or ISO 27001 Lead Auditor/Implementer are a plus.

🏖️ Benefits

• Generous performance-based bonus plans to all eligible employees—we share in our success as one team. • Rich medical, dental, and vision coverage. • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute). • Quarterly all-company wellness days where everyone takes a pause together. • Country-specific holidays plus a day off for your birthday. • One-time home office stipend. • Annual professional development budget. • Quarterly well-being stipend. • Considerable paid parental leave. • Employee referral bonus program. • Other benefits (life/AD&D, disability, EAP, etc.—varies by country).

Apply Now

Similar Jobs

🔥 5 hours ago

Flexential

501 - 1000

🤝 B2B

🏢 Enterprise

📡 Telecommunications

Physical security engineer managing access-control, CCTV, intrusion, and low-voltage systems for Flexential data centers. Leading nationwide construction, retrofit, vendor, and incident-management projects.

🔥 17 hours ago

Zscaler

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🏢 Enterprise

Principal AI Security Specialist advising Fortune 500 leaders on securing GenAI deployments for Zscaler’s Zero Trust cybersecurity platform. Driving technical sales, demos, and AI security enablement.

🔥 19 hours ago

TerraPower

501 - 1000

⚡ Energy

💊 Pharmaceuticals

Nuclear security engineer developing physical security, access authorization, and fitness-for-duty programs for TerraPower’s advanced nuclear reactor projects. Supporting NRC licensing, design compliance, audits, and security documentation.

🔥 21 hours ago

KirkpatrickPrice

51 - 200

💼 Consulting

🏥 Healthcare

⚖️ Legal

Information security auditor helping KirkpatrickPrice clients complete compliance audits and strengthen data-protection controls. Evaluating security practices, testing controls, and guiding remediation remotely with client travel.

🕒 Yesterday

Redpanda Data

51 - 200

🏢 Enterprise

☁️ SaaS

🤝 B2B

Staff Security Engineer securing Redpanda’s streaming, SQL analytics, and agent-data governance platform. Leading AppSec, fuzzing, supply-chain security, and PSIRT across cloud and systems software.

🇺🇸 United States – Remote

💵 $210k - $247k / year

💰 $100M Series D - Redpanda Data on 2025-04

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer